What this means
Steel Security is designed to help administrators understand the current state of a WordPress site without pretending to be a full incident-response platform.
It combines explicit manual scans, grouped preventive hardening controls, an operator-reviewed quarantine workflow, and server-protection visibility into one admin experience.
What Steel Security detects
The current Free release checks PHP and WordPress exposure, public fingerprint files, dangerous registration configuration, grouped hardening gaps, root-level sensitive artifacts such as `.env` files and SQL dumps, recursive backup discovery, uploads execution protections, and current server-protection telemetry when a safe reporter is available.
Steel Security Pro adds deeper scan providers, stored history, trend tracking, scheduled scans, report generation, and scheduled email reporting.
- PHP and debug exposure
- WordPress configuration weaknesses
- Public exposure and fingerprinting risks
- Sensitive files, backup archives, and SQL dumps
- Current-state server-protection visibility for Fail2Ban and cPHulk
What Steel Security can do
Steel can apply selected hardening changes directly when the action is reversible and the environment is understood well enough to do it safely.
Examples include disabling XML-RPC, restricting REST user endpoints, renaming the default `admin` username, hiding the default login URL, and blocking PHP execution in uploads on supported server stacks.
Important limitations
Steel Security does not guarantee that a site is fully secure.
It is not a WAF, a generalized malware scanner, or a replacement for good hosting, backups, and account security.
Server-level tools such as Fail2Ban and cPHulk remain outside WordPress control. Steel can surface safe current-state telemetry for those integrations only when a server-owned reporter exports it for WordPress to read.